3 ms·
Crypto as I know it doesn't allow performing an authenticated key exchange between two entities without neither a pre-shared secret nor a trusted third party (C
by cryptbe 11y ago
Crypto as I know it doesn't allow performing an authenticated key exchange between two entities without neither a pre-shared secret nor a trusted third party (CA) [1]. Anyone who promises anything like that is either selling snake-oil or hiding some requirement. DANE still requires trusted third parties, I'm not sure why it's better than the current model.
[1] There's https://en.wikipedia.org/wiki/Merkle%27s_Puzzles https://en.wikipedia.org/wiki/Merkle%27s_Puzzles, but it's not really practical when you make it secure and not secure when you make it practical.
- tootie 11y agoYeah, this is no different than using a self-signed cert where you're personally assured it's legit.
- sargun 11y agoIt requires the trust of the DNS roots. Which is pretty neat actually: http://www.root-dnssec.org/ http://www.root-dnssec.org/ And it requires your registrar to not try to perform a malicious attack against you. But at that point, most registrars already have access to a root CA, and your domain - they could easily break your environment.